Is facebook.com legit?
This website is mostly safe, but there are some critical concerns regarding its security posture. The SSL certificate is set to expire in just 7 days, which is a major red flag for a site of this scale.
Social Media average: 80/100 · based on 38 sites
Checked: April 21, 2026 at 2:05 PM UTC
Is facebook.com a scam? Here's what we found.
While the site uses TLS 1.3 and has strong security headers like HSTS and CSP, the SSL certificate expiring in 7 days is a severe oversight, and the high number of external scripts raises concerns about potential vulnerabilities.
With a domain age of almost 30 years and clear WHOIS information, the site's identity is well-established and transparent. The domain is registered with a reputable registrar and has a long expiry date.
As one of the most visited global websites and not being on any DNS blacklists, its reputation is exceptionally strong, reflecting a long-standing and trusted web presence.
The site provides contact information, social media links, and a favicon for branding, indicating a good level of transparency, though structured data is absent.
The presence of both privacy policy and terms of service pages demonstrates a commitment to legal and user compliance.
The DNS setup is robust with multiple name servers and email authentication (SPF, DMARC), ensuring reliable communication, though the misconfigured sitemap is a minor operational flaw.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 7 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Domain created 1997-03-29T05:00:00Z (29 years, 5 months ago)
Registered through RegistrarSafe, LLC
Expires in 2899 days
DNSSEC status from WHOIS
Resolves to: 2a03:2880:f176:181:face:b00c:0:25de, 157.240.253.35
Mail servers: smtpin.vvv.facebook.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: d.ns.facebook.com., c.ns.facebook.com., b.ns.facebook.com., a.ns.facebook.com.
Excessive number of external scripts — may indicate malicious injection
Blocks unknown crawlers by default but grants access to specific bots (754 directives)
Site has a favicon but no social sharing metadata
Sitemap URL returns non-XML content
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: DENY
No threats detected by Google Web Risk
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.